CVE WATCH / VULNERABILITY DETAIL

CVE-2026-92424

MEDIUMCVSS 6.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-92424 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-92424

MEDIUMCVSS 6.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]